Skip to content

Firewall Rules

Complete firewall configuration for the UniFi Gateway.

NamePolicy TypeActionProtocolSrc. ZoneSourceDst. ZoneDestinationDst. Port
Translate Network Traffic to…Masquerade NATTranslateAll-zrh-default-v1, zrh-mgmt-v10 +4-AnyAny
FW_ALLOW_ZRH-DC-ZRH-01_DNS_EGRESSMasquerade NATTranslateAll-zrh-default-v1, zrh-mgmt-v10 +3-AnyAny
FW_ALLOW_ZRH-DC-ZRH-…FirewallAllowTCP/UDPInternal10.30.30.10External1.1.1.1, 8.8.8.853
FW_DENY_ZRH-SRV-V30_I…FirewallBlockAllInternalzrh-srv-v30ExternalAnyAny
Allow Neighbor Advertisement…FirewallAllowICMPv6ExternalAnyGatewayAnyAny
Allow Neighbor SolicitationsFirewallAllowICMPv6ExternalAnyGatewayAnyAny
Allow Return TrafficFirewallAllowAllMultipleAnyAnyAnyAny
Allow WireGuard VPNsFirewallAllowUDPExternalAnyGatewayAny51820
Allow mDNSFirewallAllowUDPInternalAnyGateway224.0.0.251, ff02::fb5353
Block 10.1.1.0/24 Internet Ac…FirewallBlockAllInternal10.1.1.0/24ExternalAnyAny
Block Invalid TrafficFirewallBlockAllMultipleAnyMultipleAnyAny
Block QUICFirewallBlockUDPInternal10.40.40.0/22ExternalAny443
Allow All TrafficFirewallAllowAllMultipleAnyMultipleAnyAny
Block All TrafficFirewallBlockAllMultipleAnyMultipleAnyAny

Allows Forest Root DC to reach external DNS for forwarding.

Source: 10.30.30.10 (srv-dc-zrh-01)
Destination: 1.1.1.1, 8.8.8.8
Protocol: TCP/UDP
Port: 53
Action: Allow
Position: BEFORE FW_DENY_ZRH-SRV-V30

Blocks all Server VLAN traffic to Internet (except explicit allows above).

Source: zrh-srv-v30 (entire VLAN 30)
Destination: External
Protocol: All
Action: Block

Forces HTTPS inspection by blocking QUIC protocol from clients.

Source: 10.40.40.0/22 (Client VLAN)
Destination: External
Protocol: UDP
Port: 443
Action: Block

In UniFi, rules are evaluated:

  1. Zone-to-Zone context selected first
  2. Rules within that context evaluated top-to-bottom
  3. First match wins
  4. Implicit deny at end

Important: Zone pairing is evaluated BEFORE individual rules!